Repository navigation
chore(r5): archive the scorecard corpus and clean path leaks (#837) - #1216
Merged
Merged
Conversation
Contributor
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 3 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (40)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
K9 contract conformancerun https://github.com/hyperpolymath/standards/actions/runs/37909784377 K9 normative contract typecheckK9 contract self-testK9 conformance fixturesK9 corpus conformance (L2) |
Ruling R5 on #837 (owner, 2026-10-09): option B, with the section 4 leak clean first. This is increment 1 of three. - Remove machine-local absolute paths from 47 lines (25 evidence, 12 system, 10 effects) of the 29 *.scorecard.a2ml records, before the move, so the archive is clean from its first commit. - Drop the generator header from each record (the recipe is gone) and repoint each "# Schema:" comment at the archived schema. - Move .machine_readable/scorecards/ (29 records + schema) to .machine_readable/archive/scorecards-v1/ and add a README tombstone. - Repoint the four consumers: .hypatia-baseline.json, docs/BADGE-CRITERIA-SPEC.adoc, 1-formats/k9/spec/MIGRATION-1058.adoc, REGISTRY.adoc. - Record the ruling and the three increments in 1-formats/deed/mappings/scorecard-corpus-decision.adoc section 5. - Exclude the archived records (only *.scorecard.a2ml, not the README and not a sibling archive) from check-canonical-names.sh and from both modes of validate-bot-directives.sh. Scan mode of the latter was red on the base tree on k9-coordination-protocol.scorecard.a2ml; it passes now. Planted-positive tests pin the narrow scope; removing either exclusion fails exactly the archive case. Pending: increment 2 (one (assessment ...) clause per spec_id) needs a chora deed for this repository; increment 3 is the estate-audit emitter. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML
hyperpolymath
force-pushed
the
chore/r5-archive-scorecards
branch
from
October 9, 2026 09:22
321f616 to
afb8a4f
Compare
Contributor
K9 contract conformancerun https://github.com/hyperpolymath/standards/actions/runs/37910884655 K9 normative contract typecheckK9 contract self-testK9 conformance fixturesK9 corpus conformance (L2) |
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Ruling R5 on #837 (owner, 2026-10-09): option B, with the §4 path-leak clean first. This PR is increment 1 of three. It freezes the spec scorecard corpus into a tombstoned archive. It does not translate the records into deeds.
*.scorecard.a2mlrecords cited the machine-local prefix/home/user/standards/(50 occurrences: 25evidence, 12systemand 10effectslines). Each prefix is removed, so every path is now repo-relative. The one bare root reference (toolchain-readiness-grades, "under /home/user/standards") now reads "under the repository root". The full file:line list is below.# Schema:comment now points at the archived schema (28 files;estate-constitutionhas none). The schema's$idis a historical identifier and is left as it is. No fact is added to any.a2mlfile..machine_readable/scorecards/(29 records +scorecard.schema.json) moves withgit mvto.machine_readable/archive/scorecards-v1/. All 30 are renames, with history kept. A newREADME.adocthere is the tombstone: frozen, do not edit, add or convert; why it was archived; what changed on the way in; what replaces it; and what it is not (the verisim-data per-repo RSR scorecards, and the OpenSSF Scorecard workflow)..hypatia-baseline.json(the SD022 entry'sfile),docs/BADGE-CRITERIA-SPEC.adoc,1-formats/k9/spec/MIGRATION-1058.adocandREGISTRY.adoc("What stays, frozen").1-formats/deed/mappings/scorecard-corpus-decision.adocgoes from "awaiting ruling" to RULED: option B. A new §5 records the three increments and what each one closes.scripts/check-canonical-names.shand both modes of.githooks/validate-bot-directives.shnow skip.machine_readable/archive/scorecards-v1/*.scorecard.a2ml. They do not skip the archive README, any other file there, or a sibling archive. The records are assessments that cite the names and tools of their day. They are not live directives, and the README forbids editing them.Refs #837. It does not close it: increments 2 and 3 remain (see Notes).
Type of change
validate-bot-directives.shscan mode (whatpre-pushruns without a diff) exits 1 on the base tree: "Codex" ink9-coordination-protocol.scorecard.a2mlL23 is a historical assessment, not a directive. It exits 0 after this PR.git grepis repointed, and thejust scorecardsrecipe and its builder were already gone before this PR. Callers outside this repo, if any, are not covered by that search.📌 New pins
afb8a4f6fcc4c66124964923b9fbcbad6505236cuses:SHA, noactions.lockentry, no lockfile record, no container digest.How has this been verified?
All commands were run locally in the worktree (Debian 13, WSL2) with
MISE_DISABLE=1.After the rebase onto
9d629d11:bash scripts/check-canonical-names.sh origin/main→no deprecated names reintroduced.wave6-canonical-names-test.sh→ 8 passed, 0 failed.validate-bot-directives-test.sh→ 10 passed, 0 failed.validate-bot-directives.shin scan mode →All files validated.git range-diff ed4f98a3..321f6165 origin/main..HEAD→1: 321f6165 = 1: afb8a4f6.bash scripts/run-shell-test-suite.sh→All 80 test file(s) passed., rc 0. That includes both edited tests.bash scripts/tests/wave6-canonical-names-test.sh→ 8 passed, 0 failed. The new case reproduces the real move: a record is committed,git mv'd into the archive and edited, so the diff is a rename carrying a+line under the new path.archive/scorecards-v2/are still blocked.bash scripts/tests/validate-bot-directives-test.sh→ 10 passed, 0 failed. It has 5 new cases: staged-mode archived record → 0; archive README → 1; sibling archive → 1; scan-mode archived record → 0; scan-mode live.deeddirective beside the archive → 1.The guards on the real change:
bash scripts/check-canonical-names.sh ed4f98a3→no deprecated names reintroduced, rc 0. With the exclusion removed, it flags0-ai-gatekeeper-protocolandrelease-pre-flight, so the exclusion is load-bearing and is reached through the rename.INPUT_PATH=. bash .githooks/validate-bot-directives.sh(scan mode) →All files validated, rc 0.git archiveof the baseed4f98a3→ERROR: .machine_readable/scorecards/k9-coordination-protocol.scorecard.a2ml contains deprecated bot directives, rc 1.No absolute path is left.
grep -E '/home/|/Users/|/root/|/tmp/|/mnt/|C:\\|~/'over the 29 archived records → 0 matches.git ls-files '*.scorecard.a2ml'→ 29, all underarchive/scorecards-v1/(acceptance item 1 of the decision spec, §3).Every added link resolves. Each new
link:target in the four edited or new.adocfiles was tested with-erelative to its file: 6 links, 0 missing..hypatia-baseline.jsonstill parses (jq -e .), and its one changed value is thefileof the SD022 entry. Its entry count is unchanged by this PR. The ratchet's205 -> 189reading below is the base's own delta frommain.bash scripts/check-exemption-ratchet.sh origin/main→Exemption ratchet: OK.bash scripts/check-standards-map.sh→GATE D PASSED.apply-baseline-test.sh,filter-sarif-by-baseline-test.shandhypatia-blocking-gate-test.sh→ rc 0..githooks/docstring-scan.sh --staged --check→ rc 0. The modifiedis_excludedand the newcksare both documented.Pre-commit and pre-push passed in full, including gitleaks, canonical names and bot directives. The first commit attempt was refused by
commit-msg(subject was 78 characters, limit 72) and was shortened. No hook was bypassed.git diff --cached --check→ clean.Checklist
git commit -S).git log --show-signaturereports a good ED25519 signature onafb8a4f6.SPDX-License-Identifier. The one new file, the archiveREADME.adoc, is prose and carriesCC-BY-SA-4.0. No existing header is changed.(assessment …)clauses and the estate-audit emitter do not exist yet.*.scorecard.a2mlin one directory, and planted positives prove that nothing else there, and no sibling archive, escapes.Notes for reviewers
(assessment …)clause perspec_id, is increment 2. It needs a<repo>_chora.deedfor this repository, which does not exist yet. Whether the canon repo's own deed carries a canon clause is an open question for that increment..a2mlwould add content to a retired format. The tombstone gains the forward link when the deed exists.estate-residue-ledger.tsv: the decision spec's §4 suggested the residue ledger, but that file is generated byscripts/spine/board.awkand checked byverify-board.sh, so a hand-added row would be lost at the next regeneration.mainat000b9f6b. One of them, anevidenceline in0-ai-gatekeeper-protocol, was rewritten by fix(main-red): repair the post-#899 red main (code + baseline triage + regen) #947 (7b05a323, 2026-09-22), so 47 remained at the base, and all 47 are cleaned here. After this PR, 0 remain.0-canon/COMPLIANCE-DASHBOARD.adoc(a frozen snapshot),RSR-SPEC-v2.adocL147 andrsr-criteria-v2.a2mlL65 (a different scorecard corpus),canon.lock(its only "scorecard" hit is the OpenSSF workflow), and the data linehypatia-rulesL69, which mentionsjust scorecardsas assessment evidence rather than as an instruction.The 47 cleaned lines (file:line on the base
ed4f98a3, under.machine_readable/scorecards/; each line held the prefix named in the Summary; content omitted)🤖 Generated with Claude Code
https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML